CRITICALAdvisoryJul 23, 2026
Action required
Immediately identify all WordPress instances in your environment and verify they are patched to the latest version. Scan web logs for REST API batch requests (/wp-json/batch) and monitor for suspicious plugin installations or webshell uploads in wp-content directories.
Affected products
WordPress CoreSearchLight CyberWizSans Technology InstituteDefiant
CVE IDs
Linked articles